Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD) @FIRSTdotorg
Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 7 hours ago
Tomo Ito (JPCERT Coordination Center, JP), Justin Murphy (DHS/CISA, US)

Working on CVD at JPCERT/CC for 9 years, Tomo currently leads the Global CVD project of the organization, which aims to contribute to the global CVD ecosystem stability through collaborations with the stakeholders from different parts of the world.

Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s), ranging from industrial control systems (ICS), operational technology (OT), medical devices, and traditional information technology (IT) vulnerabilities. Justin is involved with many other vulnerability management related efforts, including CISA's Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) work, and he serves as a co-chair for the OASIS Common Security Advisory Framework (CSAF) and OpenEoX Technical Committees. Justin is also the co-founder of the Global Community of Practice on Coordinated Vulnerability Disclosure (Global CVD-COP). Justin is a former high school mathematics teacher turned cybersecurity professional and has a M.Sc. in Computer Science from Tennessee Technological University, and a B.Sc. degree in Statistics from the University of Tennessee (Knoxville).
--
As global cyber threats become increasingly sophisticated and widespread, Coordinated Vulnerability Disclosure (CVD) serves as an essential, structured approach for timely and effective communication of vulnerability information among the affected stakeholders. The recently established Global Community of Practice on CVD (CVD-COP) is an important initiative aimed at encouraging collaboration among governmental entities and national CERTs in their roles as third-party CVD coordinators. This presentation will explore the motivations behind the CVD-COP's formation, emphasizing the critical need for CVD as a good global practice and an essential risk reduction activity.We will outline the community's key activities, including developing best practices and training materials, facilitating knowledge and experience sharing, and promoting international cooperation among stakeholders. These efforts aim to establish harmonization and enhance the effectiveness of CVD across the globe.The presentation will also review the challenges faced by the CVD-COP, such as varying levels of understanding among participants and the complexities of different governance criteria. Addressing these issues is crucial for achieving the community's objectives and realizing the benefits of harmonization for CVD practices globally. The presentation will facilitate an interactive discussion, inviting audience input on how the community can optimize its support for the vulnerability management ecosystem. By inviting participants to share their insights and experiences, we hope to identify strategies that can strengthen the CVD-COP's effectiveness and foster a collaboration among global stakeholders, including security researchers, vendors, and downstream users, ultimately promoting a more secure vulnerability management ecosystem.
Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)Lazarus Group Evolved Their Infection Chain with Old and New MalwareAI Interpretability as a Security Control: Introducing the CIRCUIT FrameworkFrom Dork to Diplomat: Communicating Coherently for Vulnerability & Incident ResponseBroken Seals, Broken Trust: Flaws and Defences in the Certificate EcosystemBringing Chronological Context to Disparate Artifacts: Accelerating Digital ForensicsQuantifying Swiss Cheese, the Bayesian WayMind Over Malware: Reducing Decision Fatigue in Incident Response TeamsSupply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?Incident Preparedness Takeaways from 5000 Exercise ParticipantsEpisode 63: John Hollenberger, Fortinet, FIRSTCON26 SpeakerRevolutionizing Malware Analysis with Agentic AI: Lessons and Innovations
FIRST |

Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER